US9338166B2

System and method for a single request and single response authentication protocol

Summary by NHIP

Single Request Authentication Protocol

The method authenticates user identities for accessing rights-protected electronic documents using a single request and single response protocol. The rights management client prevents content access and sends a request containing embedded authentication parameters to a remote server.

Claim Score by NHIP

Read claim 7, the broadest

Abstract

Various embodiments of a system and method for a single request and single response authentication protocol are described. A client may send to an authentication server a request to authenticate the identity of a user attempting to access an electronic document protected by a rights management policy. The single request may be generated according to rights management configuration information included within the document. Such rights management information may include one or more parameters for requesting authentication from an authentication server. In response to the request, an authentication server may send a single response to the client. The single response may include information indicating that the identity is authenticated (e.g., a license to access the document, or an encryption key to decrypt the document). The client system may be configured to, in response to the single response, provide access to the document according to the rights management policy.

US9338166B2, drawing sheet 1
Sheet 1 of 8

Term

7.2 yearsleft in the term

Expires 26 November 2033, including 1,848 days of term adjustment.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

36 claims: 6 independent, 30 dependent

  1. 1
    A computer-implemented method for authenticating credentials for access to a given electronic document having content protected by a given rights management policy and managed by a rights management client, comprising:receiving an indication at the rights management client of an attempt to access the electronic document having the content protected by the rights management policy, wherein said electronic document comprises rights management configuration information embedded in the electronic document that specifies access rights with respect to the content that is protected and one or more authentication parameters for performing authentication with a remote server in regard to the electronic document, wherein the rights management configuration information from said electronic document indicates a particular authentication protocol to be performed for the authentication with the remote server;responsive to the attempt to access the electronic document: the rights management client preventing access to the content of the electronic document protected by the rights management policy;and authenticating an identity of an entity attempting the access to the electronic document using a single request and single response protocol including: sending to the remote server from the rights management client, the single request to authenticate the identity of the entity attempting the access to the electronic document, wherein said single request is generated according to said rights management configuration information from the electronic document;and in response to sending the single request, receiving the single response from the remote server at the rights management client, wherein said single response comprises information indicating that said identity is authenticated;and in response to receiving the single response, the rights management client providing access to the electronic document and content that is protected according to said rights management configuration information embedded in the electronic document.
  2. 7
    Broadest claimClaim Score 45, average(NHIP)A computer-implemented method for authenticating credentials for access to a given electronic document having content protected by a given rights management policy and managed by a remote rights management client, comprising:receiving a single request from the rights management client to authenticate an identity of an entity attempting to access the electronic document having the content protected by the rights management policy, wherein said single request is generated according to rights management configuration information embedded within said electronic document that specifies access rights with respect to the content that is protected and indicates a particular authentication protocol for performing authentication in regard to the electronic document;determining whether the single request adheres to one or more authentication requirements of an authentication server;and in response to determining that the single request adheres to said one or more authentication requirements, sending to the remote rights management client a single response comprising information indicating that said identity is authenticated.
  3. 13
    A system for authenticating credentials for access to a given electronic document having content protected by a given rights management policy and managed by a rights management client, the system comprising:a memory comprising program instructions;one or more processors coupled to said memory, wherein the program instructions are executable by at least one of said one or more processors to: receive an indication at the rights management client of an attempt to access the electronic document having the content protected by the rights management policy, wherein said electronic document comprises rights management configuration information embedded in the electronic document that specifies access rights with respect to the content that is protected and one or more authentication parameters for performing authentication with a remote server in regard to the electronic document, wherein the rights management configuration information from said electronic document indicates a particular authentication protocol to be performed for the authentication with the remote server;in response to the attempt to access the electronic document: prevent, at the rights management client, access to the content of the electronic document protected by the rights management policy;and authenticate an identity of an entity attempting the access to the electronic document using a single request and single response protocol including: send to the remote server from the rights management client, the single request to authenticate the identity of the entity attempting the access to the electronic document, wherein said single request is generated according to said rights management configuration information from the electronic document;and in response to sending the single request, receive the single response from the remote server at the rights management client, wherein said single response comprises information indicating that said identity is authenticated;and in response to receiving the single response, provide, at the rights management client, access to the electronic document and content that is protected according to said rights management configuration information embedded in the electronic document.
  4. 19
    A system for authenticating credentials for access to a given electronic document having content protected by a given rights management policy and managed by a remote rights management client, the system comprising:a memory comprising program instructions;one or more processors coupled to said memory, wherein the program instructions are executable by at least one of said one or more processors to: receive a single request from the rights management client to authenticate an identity of an entity attempting to access the electronic document having the content protected by the rights management policy, wherein said single request is generated according to rights management configuration information embedded within said electronic document that specifies access rights with respect to the content that is protected and indicates a particular authentication protocol for performing authentication in regard to the electronic document;determine whether the single request adheres to one or more authentication requirements of an authentication server;and in response to determining that the single request adheres to said one or more authentication requirements, send to the remote rights management client a single response comprising information indicating that said identity is authenticated.
  5. 25
    A non-transitory computer accessible storage medium storing program instructions for authenticating credentials for access to a given electronic document having content protected by a given rights management policy and managed by a rights management client, the program instructions computer-executable to:receive an indication at the rights management client of an attempt to access the electronic document having the content protected by the rights management policy, wherein said electronic document comprises rights management configuration information embedded in the electronic document that specifies access rights with respect to the content that is protected and one or more authentication parameters for performing authentication with a remote server in regard to the electronic document, wherein the rights management configuration information from said electronic document indicates a particular authentication protocol to be performed for the authentication with the remote server;in response to the attempt to access the electronic document: prevent, at the rights management client, access to the content of the electronic document protected by the rights management policy;and authenticate an identity of an entity attempting the access to the electronic document using a single request and single response protocol including: send to the remote server from the rights management client, the single request to authenticate the identity of the entity attempting the access to the electronic document, wherein said single request is generated according to said rights management configuration information from the electronic document;and in response to sending the single request, receive the single response from the remote server at the rights management client, wherein said single response comprises information indicating that said identity is authenticated;and in response to receiving the single response, provide, at the rights management client, access to the electronic document and content that is protected according to said rights management policy configuration information embedded in the electronic document.
  6. 31
    A computer-implemented method for authenticating credentials for access to a given electronic document protected by a given rights management policy, comprising:receiving an indication of an attempt to access the electronic document protected by the rights management policy, wherein said electronic document comprises rights management configuration information specifying one or more authentication parameters for performing authentication with a remote server in regard to the electronic document server, wherein the rights management configuration information from said electronic document indicates a particular authentication protocol to be performed for the authentication with the remote server;sending to the remote server, a single request to authenticate an identity of an entity attempting to access the electronic document, wherein said single request is generated according to said rights management configuration information from the electronic document;in response to sending the single request, receiving a single response from the remote server, wherein said single response comprises information indicating that said identity is authenticated and whether the authentication parameters of the rights management configuration information have changed;and in response to the single response, providing access to the document according to said rights management policy and, if the authentication parameters of the rights management configuration information have changed, changing at least some of the authentication parameters specified by the rights management configuration information.